CVE-2017-9969 is an information disclosure vulnerability affecting Schneider Electric's IGSS Mobile application version 3.01 and earlier, where passwords are stored in clear text within the application's configuration. This flaw carries a CVSS score of 6.7 (Medium), indicating that a high-privileged local attacker could easily access sensitive information, leading to high confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Despite this, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.01CPE matchmatch criteria | cpe:2.3:a:schneider-electric:igss_mobile:*:*:*:*:*:android:*:* | ||
<= 3.01CPE matchmatch criteria | cpe:2.3:a:schneider-electric:igss_mobile:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.